Skip to main content
added 6 characters in body; edited title
Source Link
mentallurg
  • 12.7k
  • 5
  • 39
  • 51

Should iI let administrator account can bypass ip aclIP ACL?

Let's say there is a system that can set ip aclIP ACL for security. If administrator can't bypass ip aclIP ACL, account may by locked up when machine or network ipIP changed But if administrator can bypass ip aclIP ACL, then an attacker can bypass ip aclIP ACL when got administrator account. Ip acl gotIP ACL gets meaningless.

Is there good way to mitigate both situationsituations?

Should i let administrator account can bypass ip acl?

Let's say there is a system that can set ip acl for security. If administrator can't bypass ip acl, account may locked up when machine or network ip changed But if administrator can bypass ip acl, attacker can bypass ip acl when got administrator account. Ip acl got meaningless

Is there good way to mitigate both situation?

Should I let administrator account bypass IP ACL?

Let's say there is a system that can set IP ACL for security. If administrator can't bypass IP ACL, account may by locked up when machine or network IP changed But if administrator can bypass IP ACL, then an attacker can bypass IP ACL when got administrator account. IP ACL gets meaningless.

Is there good way to mitigate both situations?

Source Link

Should i let administrator account can bypass ip acl?

Let's say there is a system that can set ip acl for security. If administrator can't bypass ip acl, account may locked up when machine or network ip changed But if administrator can bypass ip acl, attacker can bypass ip acl when got administrator account. Ip acl got meaningless

Is there good way to mitigate both situation?